omh-jit-learn

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions define a legitimate research workflow focused on learning target selection and source-gated recommendations.\n- [SAFE]: No obfuscation techniques, such as Base64 encoding, zero-width characters, or homoglyph attacks, were detected. The non-English text in the routing signals consists of valid Korean translations relevant to the skill's purpose.\n- [SAFE]: No hardcoded credentials, sensitive file access, or suspicious network operations were found in the skill definitions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied learning goals and external source data, presenting an attack surface for indirect prompt injection. This is evaluated as safe due to the implementation of robust internal controls.\n
  • Ingestion points: User prompts and external source research results are the primary data inputs.\n
  • Boundary markers: The protocol mandates an explicit target confirmation step ("Learn X now so I can do/decide Y...") and a 6-round interview ceiling to prevent drifting into unintended instructions.\n
  • Capability inventory: The skill uses the omh CLI for runtime recording; it does not define additional file system or network tools that could be abused.\n
  • Sanitization: The skill employs mandatory confirmation questions and strict source-gating criteria that prioritize authority and fit over generic popularity signals.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:34 PM
Security Audit — agent-trust-hub — omh-jit-learn